not sure if this is malware or not but.......

Discussion in 'Malware Help (A Specialist Will Reply)' started by cher_hc_43, Mar 2, 2006.

  1. cher_hc_43

    cher_hc_43 Private First Class

    This morning when I turned on my other computer I noticed an icon on the desk top which i dont remember seeing there l;ast night it is trff.exe what exactly is that, and should I delete it? I ran ad-aware se and ccleaner and spybot and none of these find malware, so where in the heck did this come from?

    thank you
    cheryl

    p.s.
    this computer is currently
    running windows 98 SE
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Sounds like a baddie, let's be safe and run the READ ME.

    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis

    http://www.majorgeeks.com/images/grenade.gif When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. cher_hc_43

    cher_hc_43 Private First Class

    I am going through the processes now I am running bitdefender online scan and then I will run panda, but I noticed that you wanted me to scan in safe mode and unplug the computer from the internet, well on the computer that I am scanning it has wireless card for the internet how do I disable it? the main computer in the house has the router should I just unplug the router?

    cheryl
     
  4. cher_hc_43

    cher_hc_43 Private First Class

    I have noticed that a lot of the steps are for windows me windows xp, but my other computer is windows SE, so what steps can I do witrh that windows program? I did download the ccleaner and ran ad-aware and spybot now what do I do? Also ren bitdefender and saved that log, will do panda now.

    cheryl
     
  5. cher_hc_43

    cher_hc_43 Private First Class

    ok I ran the bitdefender and panda online scans and also booted the computer in safe mode and did the necessary scans, I am attaching the bitdefender and panda scan logs, will do the hijack this when I am done here.

    cheryl
     

    Attached Files:

  6. cher_hc_43

    cher_hc_43 Private First Class

    Here is my hijack this log

    cheryl
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. cher_hc_43

    cher_hc_43 Private First Class

    ok here is another hjt log, and I downloaded HJT again, I was running a current version that I downloaded today, let me know if this worked.

    thank you
    cheryl
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yaho o.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yaho o.com

    O16 - DPF: {72C9EA8F-8965-40C2-ABAD-D460A5815F86} (hostCntrlIE Class) - http://host.oddcast.com/hostClientIE.cab

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    After you complete the above, reboot and let me know how things are running and if any problems remain.
     
  10. cher_hc_43

    cher_hc_43 Private First Class

    ok will let you know

    thanx
    cheryl
     
  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  12. cher_hc_43

    cher_hc_43 Private First Class

    ok I ran the hijack this again and removed the items that you specified and rebooted the computer and I did a search for the trff.exe and I still found it so I deleted them to the recycle bin, I did the ccleaner after hijack this then rebooted the computer and the trff was still there, now it is sitting in my recycle bin, shoulc I do another ccleaner, and what exactly is trff, I know you said it was bad, but what was it? Not sure if the computer is doing better or not, really didnt have a problem with it, it was just that icon on the desktop that worried me. thank you for the help though, it was very much appreciated.

    cheryl
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It's just a typical malware related file. When you delete it, hold down SHIFT so it deletes it without going to the recycle bin.
     
  14. cher_hc_43

    cher_hc_43 Private First Class

    Ok was able to delete them, everything is running fine, thank you for all your help. You guys are great!

    cheryl :)
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds